logo

A Guide to Threat Hunting in a SOC

ID: 2a4492a0-c7ff-559e-ae46-339106afc1d2

STIX ID: report--2a4492a0-c7ff-559e-ae46-339106afc1d2

Feed Name: On the Hunt

Threat Score
45/100

Date Published: 2021-06-28

Date Updated: 2026-04-19

Author: Paul Newton

...
...

**Executive summary:** This post advocates a proactive, research-driven threat hunting approach and demonstrates practical hunts for lateral movement using Cobalt Strike and Impacket (e.g., WMIExec and Cobalt Strike Jump), providing example Sysmon events, command-line patterns, registry/service artifacts, admin-share file paths, sample queries, and a recommended hunt lifecycle to convert high-confidence hunts into detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.